Re: Name Constraints

2015-03-09 Thread Phillip Hallam-Baker
On Mon, Mar 9, 2015 at 11:38 AM, Michael Ströder wrote: > Ryan Sleevi wrote: > > Given that sites in consideration already have multiple existing ways to > > mitigate these threats (among them, Certificate Transparency, Public Key > > Pinning, and CAA), > > Any clients which already make use of C

Re: Name Constraints

2015-03-09 Thread Ryan Sleevi
On Mon, March 9, 2015 8:38 am, Michael Ströder wrote: > Any clients which already make use of CAA RRs in DNS? > > Or did you mean something else with the acronym CAA? > > Ciao, Michael. CAA (RFC 6844) is not for clients. It's for CAs, as another way of restricting CAs authorized to issue for a

Re: Name Constraints

2015-03-09 Thread Michael Ströder
Ryan Sleevi wrote: > Given that sites in consideration already have multiple existing ways to > mitigate these threats (among them, Certificate Transparency, Public Key > Pinning, and CAA), Any clients which already make use of CAA RRs in DNS? Or did you mean something else with the acronym CAA?